Vulnerabilities > AMD > Epyc 7551P Firmware

DATE CVE VULNERABILITY TITLE RISK
2021-11-16 CVE-2021-26320 Improper Certificate Validation vulnerability in AMD products
Insufficient validation of the AMD SEV Signing Key (ASK) in the SEND_START command in the SEV Firmware may allow a local authenticated attacker to perform a denial of service of the PSP
local
low complexity
amd CWE-295
5.5
2021-11-16 CVE-2021-26321 Command Injection vulnerability in AMD products
Insufficient ID command validation in the SEV Firmware may allow a local authenticated attacker to perform a denial of service of the PSP.
local
low complexity
amd CWE-77
5.5
2021-11-16 CVE-2021-26330 Out-of-bounds Write vulnerability in AMD products
AMD System Management Unit (SMU) may experience a heap-based overflow which may result in a loss of resources.
local
low complexity
amd CWE-787
5.5
2021-11-16 CVE-2021-26331 Unspecified vulnerability in AMD products
AMD System Management Unit (SMU) contains a potential issue where a malicious user may be able to manipulate mailbox entries leading to arbitrary code execution.
local
low complexity
amd
7.8
2021-11-16 CVE-2021-26335 Unspecified vulnerability in AMD products
Improper input and range checking in the AMD Secure Processor (ASP) boot loader image header may allow an attacker to use attacker-controlled values prior to signature validation potentially resulting in arbitrary code execution.
local
low complexity
amd
7.8
2021-11-16 CVE-2021-26312 Exposure of Resource to Wrong Sphere vulnerability in AMD products
Failure to flush the Translation Lookaside Buffer (TLB) of the I/O memory management unit (IOMMU) may lead an IO device to write to memory it should not be able to access, resulting in a potential loss of integrity.
local
low complexity
amd CWE-668
5.5
2021-11-16 CVE-2021-26322 Use of Insufficiently Random Values vulnerability in AMD products
Persistent platform private key may not be protected with a random IV leading to a potential “two time pad attack”.
network
low complexity
amd CWE-330
7.5
2021-11-16 CVE-2021-26329 Integer Overflow or Wraparound vulnerability in AMD products
AMD System Management Unit (SMU) may experience an integer overflow when an invalid length is provided which may result in a potential loss of resources.
local
low complexity
amd CWE-190
5.5
2021-06-11 CVE-2020-12988 Unspecified vulnerability in AMD products
A potential denial of service (DoS) vulnerability exists in the integrated chipset that may allow a malicious attacker to hang the system when it is rebooted.
network
low complexity
amd
7.5